CISA et al. (2023, June 14). UNDERSTANDING RANSOMWARE THREAT ACTORS: LOCKBIT. Retrieved February 5, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can identify and terminate specific services. |
| T1070.004 File Deletion |
MalwareLockBit 3.0 | LockBit 3.0 can delete itself from disk. |
| T1480 Execution Guardrails |
MalwareLockBit 3.0 | LockBit 3.0 can make execution dependent on specific parameters including a unique passphrase and the system language of the targeted host not being found on a set exclusion list. |
| T1486 Data Encrypted for Impact |
MalwareLockBit 3.0 | LockBit 3.0 can encrypt targeted data using the AES-256, ChaCha20, or RSA-2048 algorithms. |
| T1489 Service Stop |
MalwareLockBit 3.0 | LockBit 3.0 can terminate targeted processes and services related to security, backup, database management, and other applications that could stop or interfere with encryption. |
| T1490 Inhibit System Recovery |
MalwareLockBit 3.0 | LockBit 3.0 can delete volume shadow copies. |
| T1569.002 Service Execution |
MalwareLockBit 3.0 | LockBit 3.0 can use PsExec to execute commands and payloads. |
| T1614.001 System Language Discovery |
MalwareLockBit 3.0 | LockBit 3.0 will not affect machines with language settings matching a defined exlusion list of mainly Eastern European languages. |
| T1685 Disable or Modify Tools |
MalwareLockBit 3.0 | LockBit 3.0 can disable security tools to evade detection including Windows Defender. |
| T1685.005 Clear Windows Event Logs |
MalwareLockBit 3.0 | LockBit 3.0 can delete log files on targeted systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.